OS Command Injection in CVS - CVE-2017-12836

 

OS Command Injection in CVS - CVE-2017-12836

Published: June 25, 2020


Vulnerability identifier: #VU29260
CSH Severity: High
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber
CVE-ID: CVE-2017-12836
CWE-ID: CWE-78
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
CVS
Software vendor:
cvshome.org

Description

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to improper input validation when processing characters in the URL of a remote repository within SSH client.  A remote attacker can trick the victim to use a specially crafted connection URL, inject and execute arbitrary OS commands on the client's system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Remediation

Cybersecurity Help is currently unaware of any official solution to address this vulnerability..

External links